CVE-2025-25724
CVSS 3.1 Score 4 of 10 (medium)
Details
Published Mar 2, 2025
CWE ID 252
Summary
CVE-2025-25724 is a vulnerability affecting the list_item_verbose function in tar/util.c of libarchive before version 3.7.8. This issue stems from a failure to verify the return value of the strftime function, which could result in a denial of service or unspecified other impacts. Maliciously crafted TAR archives with verbose value 2 can potentially cause this vulnerability to manifest, with a 100-byte buffer being insufficient for custom locales.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Libarchive
Affected Vendors
- Libarchive